Last updated September 18, 2026
Privacy Policy
This policy explains what information Aleen collects, why we need it, who processes it, and the choices you have. Our separate U.S. Consumer Health Data Notice provides additional detail for users covered by U.S. consumer-health privacy laws.
1. Who we are and the scope of this policy
Aleen is a personalized fitness and nutrition coaching application for adults operated by Kobas Labs LLC, a Delaware limited liability company in the United States. In this policy, “Aleen,” “we,” “us,” and “our” refer to Kobas Labs LLC as operator of the Aleen mobile app and aleen.fit.
This policy applies to the Aleen mobile app, our website, support, and related services offered in the United States, South Africa, and Mozambique. Aleen is not a healthcare provider and is not a HIPAA-covered medical service.
Contact us at privacy@aleen.fit, +1 617 602 8027, or Kobas Labs LLC, 2093 Philadelphia Pike, Claymont, Delaware 19703, United States.
2. Information we collect
- Account and authentication: name, email address, account identifier, sign-in provider, and login/security metadata. Passwords are handled by our authentication provider; we do not receive them in readable form.
- Profile and body information: age, height, weight, goal weight, units, time zone, goals, experience, equipment, schedule, and preferences.
- Consumer health data you choose to provide: health conditions, GLP-1 or other weight-management medication status, pregnancy, postpartum and breastfeeding status, cycle information, symptoms, sleep, stress, injuries, restrictions, and free-text health details.
- Fitness and nutrition activity: plans, exercises, sets, repetitions, weights, completed or missed sessions, swaps and reschedules, meal choices and logs, dietary preferences, avoided foods, and check-ins.
- Connected Health, if available and you enable it: read-only daily summaries for the source categories you approve: steps, active energy, workout count and total duration, sleep duration, body weight, and resting heart rate. The app aggregates permitted records by local day on your device before upload. Aleen does not receive minute-by-minute heart-rate samples, exercise routes, device identifiers, clinical records, medication records, or blood-glucose records through this feature.
- Coach communications: messages you send to the coach, its replies, confirmed profile updates, and safety classifications.
- Feedback: optional ratings of whether an explanation was helpful or whether the current week fits your life, and product feedback you choose to submit, including its category, message, optional permission to contact you, app version, platform, and timestamps.
- Derived information: estimates and inferences such as energy and macro targets, BMI, training volume, adherence, e1RM and personal-record estimates, recovery mode, cycle phase, progress trends, and plan adjustments.
- Device and service data: IP address, device/platform information, app version, timestamps, crash/security logs, and a notification token if you enable notifications.
- First-party product events: after sign-in and consent, supported builds record a limited list of account-attributed events such as onboarding step positions and validation failures, paywall openings, purchase or restore outcomes, plan generation/reveal, completed Aleen workouts, and app returns. These include event/session identifiers, timestamps, platform and app version/build. Restricted operator dashboards show aggregate counts. Events contain no free text, health answers, exercise details, meal, audio or coach-message content, or connected-health data, and are not used for advertising.
- Purchases: if paid subscriptions are offered, subscription status and transaction identifiers from the mobile app store that processed the purchase. We do not receive full payment-card numbers.
- Launch list and website attribution: if you join the launch list, we collect your email address and may record browser locale, referring website host, and UTM campaign fields. The launch form does not collect health, medication, workout, or nutrition information.
The Aleen mobile app does not request photos, contacts, precise location, or advertising identifiers. Connected Health is optional, read-only, available only in supported builds, and requested only after you review the disclosure, choose Continue, and separately authorize source categories in the system screen. You can approve only some categories, and refusing or revoking access does not block the rest of Aleen. If you choose optional voice input, Aleen requests microphone and speech-recognition access only after you tap Speak, uses on-device recognition to create editable text, and does not upload or retain microphone audio. You can always type instead.
3. How we use information
- create, display, and adapt your training and nutrition plan;
- provide the coach, progress, reminders, check-ins, safety screening, and account support;
- authenticate users, prevent abuse, debug failures, audit plan quality, and secure the service;
- respond to feedback, understand recurring product problems, and use structured plan-fit signals within the bounded longitudinal adaptation rules described in the app;
- measure aggregate onboarding friction, purchase outcomes, first-plan and workout activation, and returning usage so we can find product failures and improve the service;
- if you enable Connected Health, synchronize and display a daily movement and recovery snapshot inside your account. In this release these summaries do not prefill check-ins or personalize or change your training or nutrition plan;
- meet legal obligations, enforce our Terms, and investigate incidents; and
- improve product reliability using aggregated or de-identified analysis where practical.
We do not sell personal or consumer health data. We do not use health data for targeted advertising.
Connected-health summaries are not sent to product analytics, crash reporting, advertising, marketing, AI or large-language-model providers, Prism, data brokers, or model-training systems. Active energy is movement context only: it does not add food or subtract calories. An imported workout is not marked as a completed Aleen strength session.
Depending on the information and your location, we process information to perform our contract with you, with your consent (including explicit health-data and processor consent), for legitimate interests such as security and service reliability, and to meet legal obligations. You may withdraw health-data consent in Settings; Aleen then stops future health-data processing and signs you out.
4. AI processing
Recipient and purpose: Aleen sends information through Anthropic’s Claude API for coach replies, safety checks on messages and replies, and internal structured plan review. Aleen’s deterministic engines, not the AI reviewer, decide the core plan’s numbers.
- Coach requests: your message and recent conversation; your name, goals, preferences, local date and time zone; relevant health details you provide, including conditions, medication status, pregnancy or postpartum status, cycle information, sleep, stress, injuries, supplements and free-text notes; your current training and nutrition plan and summaries of recent workouts and weigh-ins.
- Safety checks: message or generated reply text and relevant known conditions, to identify potentially unsafe content.
- Internal plan review: a structured summary of goals, condition and injury categories, training frequency, session duration, exercises and nutrition targets, without your name or free-text notes.
Apple Health and Health Connect imports and microphone recordings are not sent to Anthropic. Anything personal you type in a coach message is part of that message. Only share information you want the coach to use.
Before AI processing, the app identifies Anthropic and explains these data categories and purposes, then asks for your explicit agreement using an initially unchecked choice. An older consent does not automatically count as agreement to a revised disclosure. You can decline by signing out or deleting your account, or withdraw consent later in Settings. Personalized Aleen services cannot continue without the required consent; account deletion remains available.
Our commercial AI provider is Anthropic. Under its commercial API terms, API inputs and outputs are not used to train its models by default. Standard API data is generally retained for up to 30 days, subject to limited safety, legal, or separately agreed exceptions. Internal plan-review output does not reach you directly; deterministic safety checks and plan rules remain authoritative.
AI can be wrong. Aleen prohibits medical diagnosis, treatment, medication instructions, and emergency reassurance. See our Safety & Medical Boundary.
5. When information is disclosed
We disclose only what is needed to service providers acting for us:
- Supabase for authentication, database, and storage infrastructure;
- Railway for API hosting and operational logs;
- Anthropic for the limited AI processing described above;
- RevenueCat for subscription entitlement and purchase-state management;
- Sentry for privacy-minimized crash reporting; Aleen disables screenshots, view hierarchy, request bodies, default personal data, and user-authored exception text;
- Expo and operating-system providers for notifications and app delivery; and
- Mobile identity and app-store providers if you use their sign-in or purchase services;
- Vercel for the public website and its operational security; and
- Resend for transactional and launch-list email delivery.
We require service providers processing personal data on our behalf, including our AI provider, to provide the same or an equivalent level of protection as described in this policy. Their processing is limited to the information and purposes needed for their role, with contractual confidentiality, security, and data-protection obligations. Sharing data with a processor does not remove our responsibility for the protections and choices described here.
For Anthropic, these safeguards are set out in its Data Processing Addendum, incorporated into its commercial API terms. It covers processing instructions, confidentiality, security measures, assistance with data-rights requests, and protective obligations for subprocessors. This does not mean data is retained indefinitely or used without your prior consent; the purposes, exclusions, and retention limits described above still apply.
We may also disclose information if required by law, to protect people or the service from serious harm or fraud, or in a business transaction subject to appropriate safeguards and notice. We do not disclose health data to data brokers or advertising networks.
We operate from the United States and use providers that may process information in the United States or other countries. Where information crosses borders, we rely on your consent, service-performance necessity, and contractual or other safeguards required by applicable law. Protections described in this policy continue to apply to our handling of the information.
6. Retention and deletion
We retain account, plan, activity, coach, feedback, and limited product-event data while your account is active because it powers longitudinal personalization, support, conversion diagnosis, and product reliability. Optional connected-health summaries remain while the connection and account are active, or until you use Disconnect and delete imported data. When you delete your account, Aleen deletes the account and associated active-service data, including profiles, plans, logs, messages, feedback, product events, connected-health summaries, connection metadata, Connected Health consent records, and notification tokens. Deletion does not automatically cancel a subscription managed by an app store.
Revoking access in the source health service stops future imports. Because Aleen reconciles the recent records still visible on your device, a later refresh may also remove recent summaries that are no longer available from the source. Use the separate Disconnect and delete imported data control to ensure that all imported summaries, connection metadata, and Connected Health consent records are removed from Aleen without deleting anything held by the source service.
Service-provider logs and AI requests follow the providers’ limited operational retention schedules. Data isolated in backups is not used for ordinary processing and is deleted as backups expire, and no later than six months after a verified deletion request where consumer-health law requires that deadline. We may retain a minimal record if law requires it or to establish that a request was completed.
Launch-list data is kept until the launch message is sent, you ask to leave the list, or the list is retired. Every marketing or launch email will provide a way to unsubscribe. You may also leave the list by emailing privacy@aleen.fit.
7. Your choices and rights
- access and correct information through the app or a verified request;
- withdraw consumer-health-data consent in Settings, which stops future health-data processing and removes notification tokens;
- manage source permissions in your device’s health settings, or disconnect Connected Health and delete Aleen’s imported summaries independently of the rest of your account;
- delete your account in Settings or follow the instructions on our Delete Account page;
- request access, correction, deletion, a list of relevant third parties, or appeal a denied request by emailing privacy@aleen.fit.
We verify requests to protect the account. We generally respond within 45 days and explain any permitted extension or denial. Authorized agents may submit requests where applicable, subject to verification.
South Africa. South African users may exercise rights available under the Protection of Personal Information Act, including requesting access or correction, objecting to certain processing, withdrawing consent, requesting deletion where applicable, and lodging a complaint with the Information Regulator. Health information is treated as special personal information and is processed only for the disclosed Aleen purpose and with the required permission or lawful basis.
Mozambique. Mozambican users may ask what personal data we hold, request correction of inaccurate information, object to or withdraw consent for processing where applicable, and request deletion subject to legal and operational retention duties. Send requests to privacy@aleen.fit.
Automated recommendations. Aleen uses deterministic rules and limited AI processing to personalize coaching, but does not use solely automated processing to make decisions that create legal or similarly significant effects. Contact support if you want us to review an account or plan concern.
8. Security, age, and changes
We use access controls, private databases, encrypted network connections, service-role isolation, and monitoring appropriate to the sensitivity of the information. No system can guarantee absolute security. If a breach triggers notice duties, we will provide required notices.
Aleen is for adults aged 18 and older. We do not knowingly collect personal information from children.
We may update this policy. We will change the date above and, when a material change affects consent or health-data use, provide prominent notice and request new consent where required.
9. Contact
Privacy questions or requests: privacy@aleen.fit. Product support: support@aleen.fit.
Kobas Labs LLC, 2093 Philadelphia Pike, Claymont, Delaware 19703, United States · +1 617 602 8027.
Optional WHOOP connection
In supported builds and for accounts included in the staged rollout, you can separately authorize a read-only WHOOP connection. When you request a read, WHOOP sends Aleen the latest seven days of sleep duration, recovery score, RMSSD heart-rate variability, resting heart rate, physiological-cycle strain, and workout strain and duration, with record timestamps and scoring status. This is separate from Apple Health and Health Connect; “cycle” here means a WHOOP activity/recovery cycle, not menstrual-cycle data.
Our server retrieves the authorized records and prepares a limited display in memory. Raw records and displayed summaries are not written to Aleen databases, backups, logs, or analytics. The mobile display is held only in memory and clears when you close the WHOOP screen or leave the app. This release does not send WHOOP values to AI providers, use them for advertising or model training, or use them to change training or nutrition plans. There is no background health-data synchronization.
We store encrypted connection tokens, the Aleen account identifier, granted permissions, consent version, and connection/read timestamps in our server-controlled infrastructure, including Railway and Supabase. Tokens never go to the mobile client. These connection records allow the requested read and renewal of authorization; they contain no WHOOP health measurements. Our service providers process the connection on our behalf under the protections described in this policy.
You may decline WHOOP without affecting the rest of Aleen. Disconnect WHOOP removes active-service tokens and pending authorization records and requests revocation at WHOOP; if remote revocation cannot be confirmed, the app says so and you can remove Aleen in WHOOP’s connected-app settings. Account deletion removes associated connection records. Encrypted connection metadata may remain in restricted infrastructure backups for the backup period described in the Privacy Policy; it is not used for further reads. Records held by WHOOP are not deleted by Aleen. Contact privacy@aleen.fit for access or deletion questions.